Senin, 14 November 2011

Ebook : XSS Attack - Cross Site Scripting Exploits and Defense


PUBLISHED BY- Syngress Publishing, Inc. ISBN-10: 1-59749-154-3
ISBN-13: 978-1-59749-154-9

This book is all about XSS. It will cover these topics on XSS.

Cross-site Scripting Fundamentals.
The XSS Discovery Toolkit
XSS Theory
XSS Attack Methods
Advanced XSS Attack Vectors
XSS Exploited
Exploit Frameworks
XSS Worms
Preventing XSS Attacks

Download: Ebook XSS Attack

BackTrack 5 R1


Backtrack-linux.org  has released BackTrack 5 R1. BackTrack 5 R1 contains over 120 bug fixes, 30 new tools and 70 tool updates.The kernel was updated to 2.6.39.4 and includes the relevant injection patches.


About Backtrack
BackTrack is a very popular Live DVD Linux distribution that focuses on system and network penetration testing, featuring analysis and diagnostic applications that can be run right from the CD. BackTrack emerged from Whax and Auditor Security Collection distributions, using what was best from both in one complete solution.

According to the guys at OffSec, This release is their best one yet! Some pesky issues such as rfkill in VMWare with rtl8187 issues have been fixed, which provides for a much more solid experience with BackTrack.We’ve have Gnome and KDE ISO images for 32 and 64 bit (no arm this release), as well as a VMWare image of a 32 bit Gnome install, with VMWare Tools pre-installed.We are mighty excited and are already downloading this release just as we speak!


Download BackTrack 5 R1

Android Facial Recognition Unlock Can be Hacked Using Digital Photo

 
Android facial recognition Unlock feature can be hacked using digital photo.  Google Android provide feature "Ice Cream Sandwich" that unlock a phone via Facial recognition.

A blogger showed the facial recognition technology can be fooled if it is presented with a digital picture.

"While some of you think that it is a trick and I had set the Galaxy Nexus up to recognise the picture, I assure you that the device was set up to recognise my face. I have a few people there watching me do the video and if any one of them is watching this video I hope you can confirm that this test is 100% legit," he said in a YouTube video.

It is going to be work if the attacker has your digital photo.   Thief can't recognize whose phone is ,so he can't be unlock it.

Demo :


#Anonymous : Now is the Time to evolve or Die



Anonymous was formed and birthed on the internet message board 4chan in 2003. The moniker Anonymous was derived as homage to 4chan. At the time, if someone posted to 4chan’s forums and no name was given then the post was credited to "Anonymous". Seizing onto the premise or the idea that actions can be taken anonymously by the lesser or powerless “Anonymous” moved beyond 4Chan and morphed into sometime larger and more potent. The original premise of “Anonymous” appeared to be a limited but noble idea; attempting to keep the internet open and free because governments and corporations were earnestly trying and demanding limits and restrictions to the freedom of expression on the internet.

To date “Anonymous” has remained a banner that many channers, as well as hacktivists and IRC users, post under and are loosely grouped together. Allied under the umbrella of “Anonymous” with no real command structure in the group, “Anonymous” remains an ever fluctuating mass of unknown identities that have often fancied themselves as cyber-avengers unfocused and more often than not unable to remain of the same consciousness even on an hourly basis.

History must be remembered and never forgotten, for the factual words of Italian fascist Benito Mussolini was stated correctly; “Fascism is Corporatism”.

As the gap in wages world wide become increasingly more disparaging a significantly increasing numbers of world citizens are being harmed and maltreated by the unquenchable greed and corruption of the evolving corporate state. As the wealth of the world has rapidly been consolidated into the hands of a small minority, governments are being bought and paid for and rapidly, one by one, turned over lock stock and barrel to faceless Corporations. These greed drive soulless concerns have not hesitated to use their power as an instrument of war as a means of increasing their power and profits. Sadly, as expected along with this ever grown trend it has become a fact that human rights violations are becoming even more extreme and cruel.

Since it is evident that the monstrous Corporations committing these unspeakable crimes are almost never held accountable, it is time that the young and the computer literate around the world educate themselves and become consciously aware which greedy Corporations are committing the horrendous crimes that effects the very survival of this planet and every living being on it. Because information is power, inform yourselves. Now is the time to educate yourselves and make your lists of these offenders!

By becoming more educated and informed on the global threat posed by corporations, is it possible that this idea, this premise of “Anonymous” could be channeled into the kind of tool needed to awaken global consciousness to the treachery of the global power structure. Could the true center of “Anonymous” that idea that “Anonymous” wishes to represent the truth to the world morph once more beyond its present form and limitations or will the nebulous vision behind the premise of “Anonymous” remain content to use their collective abilities for either good or bad simply content on a myopic and undisciplined path, depending on the inclination of the mob?

It is time to get off that fluffy cloud of illusion, get educated and get informed beyond such a small focus. Investigate the bigger picture, know your own power; inform others of the immediate threat of corporations and the growing take over of world governments, the biggest and baddest being taken over by fascism today is the United States of America. Internet freedom is the least of your worries now. Call it what you will, this is what Benito Mussolini correctly labeled Fascism my brothers. If you don't like it, you can oppose it. But if you ignore it and deny it; then you will remain a sitting target. “Now is the time to evolve or die”


~thehackernews.com~

Operation Brotherhood Shutdown : Multiple Sites Taken Down by Anonymous Hackers


Anonymous Hackers take down the The Muslim Brotherhood websites. The hacking group had made an announcement Tuesday in which they threatened to launch “Operation Brotherhood Takedown,” on all Brotherhood sites at 8pm on Friday, 11 November.

According to a video released by them on youtube as shown above. They claim to taken down following sites:


As of 2:24 PM EST, ikhwanonline.com IS DOWN.
As of 2:26 PM EST, ikhwanweb.com IS DOWN.

The Brotherhood claimed in a statement released on Saturday morning that the attacks were coming from Germany, France, Slovakia and San Francisco in the US, with 2000-6000 hits per second. The hackers later escalated their attack on the site to 380 thousand hits per second.Under the overload, four of the group’s websites were forced down temporarily.Anonymous is made up of a group of unidentified hackers who have previously attacked Israeli, Russian and NATO sites.

"...Therefore, Anonymous has decided to destroy the Muslim Brotherhood. We shall proceed to dismantle any form of its organization from the internet. Nothing will stop us. We will show no mercy."

Complete Press Release:
Citizens of the World,   
We are Anonymous. 

Ever since its revolution that shook the world, Egypt has had its fate undecided. Predators who seek to control are waiting to strike at the right moment. They are waiting to take over the country and make it so that another revolution is impossible. We cannot allow this. 
The Muslim Brotherhood has become a threat to the revolution Egyptians had fought for, some with their lives. They seek to destroy the sovereignty of the people of Egypt as well as other nations including the United States. 
The Muslim Brotherhood started as a benevolent group of people with fair and just intentions. However, as decades went by, corruption seized its mission of good and turned it into a power-hungry organization bent on taking over soverign arab states in its quest to seize power from them. They say this is necessary in order to unify the muslim nations into one islamic state, which is a lie. 
We will not allow this to happen. 
Their tactics are very similar to tactics used by the Church of Scientology and ideas implemented in Freemasonry. A person may join only when presented in front of the Grand Master, or the Murshid, and is ordered to adhere to a solemn vow, to follow all orders of the Murshid, without hesitation. They claim to be anti-freemasonry, however they follow distinct principles taken from it. If you were to leave the Brotherhood or present any threat to it, they would take it to offense and begin to intimidate you and put your life as well as your loved ones in danger. This has been experienced by many former followers of the Brotherhood, including citizens in the United States and Great Britain who realized they made a terrible mistake. The Muslim Brotherhood is a threat that must be dealt with. 
To those listening now, this is not a threat towards the religion of Islam. The Muslim Brotherhood, as well as terrorist organizations affiliating with the religion, defiled and destroyed the very essence of what the religion preaches. Therefore, the Muslim Brotherhood does not represent the true ideas of Islam. In our collective, many of us are Muslim, yet we fight against the corruption in society and the injustice that comes with it. 
Infused with its blatant, corrupt ways, the Brotherhood is now a threat to the people. 
Therefore, Anonymous has decided to destroy the Muslim Brotherhood. We shall proceed to dismantle any form of its organization from the internet. Nothing will stop us. We will show no mercy.  
Operation Brotherhood Takedown, engaged.
We are Anonymous.We are Legion.We do not Forgive.We do not Forget.Expect Us.
 ~thehackernews.com~

Source Code of ZeuS Botnet Version: 2.0.8.9


 Source Code of ZeuS Botnet Version: 2.0.8.9 from thehackernews.com

Download Now | RAR Password : zeus

‎The Hacker News Magazine - Social Engineering Edition - Issue 02


‎'The Hacker News' Magazine - Social Engineering Edition - Issue 02

Sabtu, 12 November 2011

10 Tips to Secure Your Joomla Site


Joomla is undoubtedly one of the best CMS available in the market. As more and more websites have started using Joomla, its important that the site is configured properly to prevent any security compromises. I have compiled 10 security tips to secure your joomla website.

1. Proper Hosting Environment
A properly configured server is highly recommended for your joomla website. Host your site on a server that runs PHP in CGI mode with su_php. This means that PHP runs under your own account user instead of the global Apache user and you don’t need to set insecure global permissions like CHMOD of 777.
a. Set register_globals OFF
b. Disable allow_url_fopen
c. Adjust the magic_quotes_gpc directive as needed for your site. The recommended setting for Joomla! 1.0.x is ON to protect against poorly-written extensions. Joomla! 1.5 ignores this setting and works fine either way.
d. Don’t use PHP safe_mode
2. Change the Default Database Prefix (jos_)
While installation, change the default database prefix to something random. This will prevent most of the SQL injection attacks as hackers try to retrive superadmin details from jos_users table.

3. Disable FTP Layer
While installation, dont enable the FTP layer as it opens up a potential security hole since your FTP details are stored in plain text under a Joomla! configuration file. FTP layer is not required if your hosting is secured and configured properly for Joomla.

4. Change superadministrator username
After installation, change the username for the super-administrator. By default, its admin. So change it something like ravi.chamria so that the username/password combination becomes difficult to guess or crack.

5. Strong password
Always use strong password for the administrator accounts. An example of strong password is E@^M!$<9@k. You can use sites like www.strongpasswordgenerator.com to generate a strong password.
A good addition is to password protect the administrator folder. In apache web server, you can do this htaccess file or in cpanel, you can use Password Protected Directory option to setup a password. This will add another layer of username/password before someone reaches your Joomla admin details. Needless to say, have this password different from Joomla admin password.

6. Enable SEF URLs
Most hackers use the Google inurl: command to search for a vulnerable exploit. So enable SEF urls from site configuration if you are using Joomla 1.5. You can also use extensions like SH404SEF for both Joomla 1.0 and Joomla 1.5. This will prevent hackers from finding the exploits as well as benefit you in SEO perspective.

7. Upgrade to latest release of Joomla
Always upgrade to the latest release of Joomla as soon as possible. Always download Joomla! from official sites, such as the Joomla! Forge, and check the MD5 hash

8 Third party extensions
There are more than 4000 extensions available for Joomla many of which are non-commercial. But dont take this as an opportunity to install unnecessary extensions on your website. Remember that most hacking attempts occur due to vulnerability in these extensions. So, always use extensions which are popular, has strong community backing and development process.

9. Proper file/folder permissions
The proper file/folder permissions for your joomla website is:
* PHP files: 644
* Config files: 666
* Other folders: 755
You can CHMOD the files and folders using your FTP client.

10. Setup a backup and recovery process
Always rely on a strong backup and recovery protocol for your live website. Its not just hacking that may compromise your website but other factors like a faulty upgrade or extension install, hardware failure, hosting provider issues. You can use JoomlaPack, a non-commercial component native for both Joomla 1.0 and 1.5 for backup.

Secure Your Joomla Before They Are Hacked


I have some tips to secure your Joomla website.


* Follow the Joomla Administrator's Security Checklist
The guys at joomla.org have put together a Joomla Administrator's Security Checklist - use it and secure your Joomla site as much as possible using the guidelines.

* Install the jSecure Authentication plugin
Every Joomla back-end has the same URL. If you install a security plugin, you can add a suffix to your back-end URL to make it look like this: http://www.yoursite.com/administrator?helloworld
If the URL is not entered with a correct suffix, the site will redirect to a 404 (not found) page. Change the suffix regularly. The plug-in is $4.99 and it's worth it!
Buy and download the jSecure Authentication plugin here

* Don't use the jos_ prefix
The standard prefix for Joomla tables are jos_. However, many security exploits rely on your database tables being called jos_XXXXXX.
By simply using your own prefix you would have been protected from these exploits.
It should also be unique for every site.
Read more about this over at the blog of Brian Teeman.

* Change your admin user
The default ID for the admin user in Joomla is always 62, and this may be used by a hacker. To avoid this, do the following:
# Create a new super-administrator with another user name and a strong password
# Log out and in again as this new user
# Change the original admin user to a manager and save (you are not allowed to delete a super-administrator).
# Now, delete the original admin user (user ID 62).
* Create a unique passwords from a combination of upper- and lowercase letters, numbers and symbols. For instance WsHc3_#7
Use an Online Password Generator to make the process easier.

* Change your username and password often At least every 3 months.

* Don't use the root user in mySQL as the user of your database
You should always create a new database user when installing a new site, and give rights to the new database only. This way, the user will only have access to the specific site. If not, you can have one site hacked and the rest are wide open as well...

* Always update to the latest Joomla version

Free Joomla Template : CloudAccess 2.0


CloudBase 2.0 is an advanced template created by CloudAccess.net. It's based on Gantry Framework developed by RocketTheme.

Features :
Additional features we created on top of those Gantry offers:
* 11 template presets (color variations),
* 10 background patterns,
* One of the most advanced system of picking colors for each template element,
* improved "Scroll to top" feature,
* Equal height for modules,
* 60 module positions.

Gantry features:
* 960 Grid System (http://960.gs) for simple consistent layout. 12 and 16 column support
* Per-menu control over all Gantry functionality
* Ability to save/remove custom presets
* Built-in AJAX Support
* iPhone and iPod Touch mobile autotheme support
* Built-in Gantry RokGZipper to compress and combine Gantry JS and CSS files
* Cleaner more understandable index.php.
* Flexibility to configure up to 6 modules in row position.
* 36 possible combinations for the layout of the mainbody/sidebars alone!
* Flexibility to configure different grid-size layouts based on number of published modules. You are not forced to use the same grid layout for every page
* 12 built-in Gantry Features like Logo, font-sizer, to-top smooth slider.
* Ability to force module display and 'blank' module positions for advanced module placement ability.
* Stunning new Admin interface providing better usability and control.
* Unique Layout controls allow you to configure your layout without having to do math.
* Layout controls provide visual representation of your front-end layout for simple and intuitive customization.
* Gantry is XML driven, adding another row of completely flexible module positions is as simple as editing one XML file.
* New flexible parameter system allows loading preset theme attributes and modifying for a custom design.
* All new table-less HTML overrides based on the excellent GNU/GPLv2 overrides from YOOtheme (http://www.yootheme.com)
* New standard typography and Joomla core elements styling
* New advanced caching system makes using Gantry really fast!
* All configuration state is stored in params.ini and cached for speed.
* Optimized codebase with speed, size, and reuse core tenants of the framework design